TL;DR: The number of AI agents discovered in customer environments typically lands two to five times higher than what organisations believe is present, with one hospitality deployment showing a more than fivefold gap and twelve high-risk agents uncovered in the first scan, according to Onyx. Inventory accuracy, attribution, and continuous visibility are now governance prerequisites, not optional audit work.
At a glance
What this is: Onyx reports that first-pass AI agent discovery regularly finds environments that are two to five times larger than the customer believed, revealing a structural inventory and attribution gap.
Why it matters: IAM, IGA, and security teams need continuous visibility into AI agents because undocumented agents, borrowed credentials, and embedded agentic features can expand access faster than governance workflows can track.
👉 Read Onyx's analysis of AI agent discovery gaps and onboarding findings
Context
AI agent discovery is no longer a theoretical exercise, because organisations are already deploying agentic systems through software updates, embedded features, and informal engineering workflows. The primary governance problem is that the security team often does not have a reliable inventory of what exists, what it can access, or who is accountable for it.
For AI agent governance, the first control gap is visibility. A central register that only reflects approved procurements will miss embedded agents, user-activated agents, and internally built agents, which means access reviews, policy enforcement, and incident response all start from an incomplete baseline.
This is the same structural issue that has long affected NHI programmes, but AI agents add faster change and weaker attribution. Teams need a way to identify not just the existence of agents, but the credentials they use, the data they reach, and the lifecycle owner attached to each one.
Key questions
Q: How should security teams handle AI agent discovery when approved inventories are incomplete?
A: Security teams should treat approved inventories as a starting point and query the environment directly. The goal is to reconcile embedded agents, user-activated agents, and internally built agents into one live register with ownership, access scope, and review status. If the inventory cannot be refreshed continuously, it is not a control.
Q: Why do AI agents create more governance risk than ordinary integrations?
A: AI agents can connect quickly, run continuously, and accumulate broad permissions across multiple services. That combination makes ownership blur and scope drift more likely, so the real risk is not the tool itself but the uncontrolled access path it creates across enterprise systems.
Q: What do organisations get wrong about agent identity attribution?
A: They often treat the human prompt as the identity, when the agent itself is the actor making tool selections and execution decisions. That mistake breaks accountability because the audit record no longer shows who owned the agent, who approved its access, and which action chain it executed. Attribution must follow the agent instance, not the user's intent alone.
Q: Who should own remediation when AI finds a multi-step exploit chain?
A: The owning team should be the one responsible for the full chain, not just the first broken component. In practice that usually means AppSec, IAM, infrastructure, and service owners must triage together so a bypass, a privilege gap, and a data exposure path are fixed as one control failure.
Technical breakdown
Why AI agent inventories diverge from approved records
AI agent inventories diverge because discovery and procurement are no longer the same event. Agents enter through licensed products with embedded AI features, developer-built automations, and SaaS platforms that enable new capabilities without a formal security ticket. That means the authoritative record is usually a governance artefact, not an operational fact. In practice, the environment contains identities that were never centrally registered, never risk-ranked, and never mapped to data or systems. Continuous discovery matters because the agent population changes as fast as the product estate changes.
Practical implication: treat AI agent discovery as an always-on control, not a one-time onboarding exercise.
How agent identity attribution breaks in multi-agent workflows
Attribution breaks when an agent acts under a credential that traces back to a human setup action, shared account, or inherited token. Logs then show a human-linked identity even though the operational decision was made by an agent. In multi-agent chains, delegation amplifies the problem because each handoff can blur ownership, intent, and responsibility. This is not just a logging issue. It affects auditability, incident reconstruction, and accountability for access scope, especially when an agent reaches HR, finance, or customer data.
Practical implication: separate agent identity from human identity in logs, reviews, and escalation paths.
Why week-one scanning has to feed continuous governance
Week-one scanning is a baseline, not a conclusion. Once teams see the true number of agents, the operational challenge becomes keeping that number accurate as products update, teams build new automations, and users activate features outside central approval. Without a recurring governance cycle, the inventory decays quickly and the organisation ends up with a report instead of a control plane. That is the difference between finding agents and governing them.
Practical implication: tie discovery outputs to recurring review, ownership, and remediation workflows.
Threat narrative
Attacker objective: The objective is to exploit ungoverned AI agent access to reach sensitive systems and data before security teams can discover or constrain the agents.
- Entry occurs when AI capability is introduced through licensed software, internal workflow automation, or user-activated SaaS features that were never added to the central inventory.
- Escalation occurs when agents inherit borrowed, shared, or human-linked credentials, creating access paths that are not right-sized for the agent's actual function.
- Impact occurs when undiscovered agents reach sensitive systems such as HR records or publicly accessible operational surfaces without prior security review.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI agent inventory debt is now a governance failure mode, not a discovery nuisance. The article shows that the gap between believed and actual agent populations can reach five times, which means central inventories are structurally incomplete once agentic features are distributed through SaaS, engineering, and embedded product updates. This is not a tooling inconvenience. It is the point at which IAM, IGA, and security ownership stop describing the real environment. Practitioners should treat inventory debt as a standing control gap, not a project delay.
Agent identity attribution is the new boundary problem for NHI programmes. When logs point to a human credential but the actor was an agent, accountability becomes ambiguous and incident reconstruction loses fidelity. That is a classic NHI governance issue, but agentic behaviour makes it harder because the same credential may serve multiple execution contexts. The field needs to stop assuming that a human-linked login tells the full story. Practitioners must govern the executor, not just the credential holder.
Continuous visibility is the named control concept this category now needs. Onyx's week-one scanning pattern exposes a runtime governance gap: inventories age immediately when agents can appear through product updates and user activation. Static review cadences were designed for slower-moving identity estates and fail when the object under governance is mutable software behaviour. The implication is that AI agent governance should be measured as a living control, not a periodic audit outcome.
Existing NHI controls are still the correct baseline, but they are no longer sufficient on their own. The same lifecycle questions apply to agents as to service accounts, yet the operational tempo is different and the accountability chain is weaker. That means discovery, ownership, access scope, and review all remain relevant, but they must operate continuously and at agent speed. Security leaders should align AI agent governance to the broader NHI programme rather than treating it as a separate discipline.
The market is moving from agent enablement to agent accountability. The strongest signal in this article is not that organisations are adopting AI agents faster than expected. It is that they cannot answer basic questions about count, scope, or owner once those agents are in production. That is where governance maturity will now be measured. Practitioners should expect procurement, legal, and security teams to demand proof of continuous control rather than one-time discovery outputs.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- The same research found that lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, with inadequate monitoring and logging and over-privileged accounts each cited by 37%.
- For a broader lifecycle lens, see Ultimate Guide to NHIs , 2025 Outlook and Predictions for how inventory, ownership, and ongoing governance converge in practice.
What this signals
Continuous visibility is becoming the default expectation for AI agent governance. Once agents can appear through embedded features and user activation, periodic discovery no longer provides an accurate control baseline. Practitioners should expect agent inventories to behave like other high-churn identity estates, where ownership, review, and revocation have to be operational rather than annual. The governance model now needs to follow the runtime, not the procurement calendar.
Inventory debt will increasingly show up as audit and incident-response debt. When an environment contains more agents than the team believed, the first problem is visibility, but the second is explainability. Security leaders should prepare for questions about who owns the agent, which credential it used, and whether the data it reached was ever approved for that actor class.
With 85% of organisations lacking full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security, the adjacent lesson for AI agents is clear: unmanaged entry points will keep outrunning central registers unless discovery is tied to lifecycle control.
For practitioners
- Establish a live AI agent inventory Query the environment directly, reconcile embedded and user-activated agents, and maintain ownership for every discovered agent in a central register. The register should reflect runtime reality, not only approved procurement records.
- Separate agent identity from human identity Tag agent actions with a distinct executor identity, preserve the human setup context separately, and ensure logs can show which credential was used, which system was reached, and who owns the agent lifecycle.
- Review embedded AI features as new identities Treat product updates that add agentic capability as identity events, not feature toggles. Route them through security review before they inherit access to HR, finance, customer, or operational systems.
- Build recurring remediation into onboarding Turn week-one findings into scheduled ownership, access-rights, and risk reviews so the inventory does not decay after deployment. Use the initial scan to seed continuous governance, not to close the project.
Key takeaways
- AI agent governance fails first at visibility, because approved inventories rarely match runtime reality.
- The most serious risk is not agent count alone, but broken attribution, over-scoped access, and missing lifecycle ownership.
- Continuous discovery and recurring remediation are now baseline controls for any organisation operating at agent scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A1 | The article centres on agent discovery, runtime behavior, and identity attribution. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Undiscovered agents and borrowed credentials are classic non-human identity governance problems. |
| NIST CSF 2.0 | ID.AM-1 | Asset management is directly implicated by incomplete AI agent inventories. |
| NIST Zero Trust (SP 800-207) | Continuous verification is necessary when agent populations shift quickly. | |
| NIST AI RMF | GOVERN | AI governance ownership and accountability are central to the article's argument. |
Map agent discovery gaps to agentic identity controls and require runtime ownership for every agent.
Key terms
- AI agent inventory: An AI agent inventory is a complete record of autonomous or semi-autonomous software entities, including their permissions, tools, and reachable resources. It is a governance baseline because teams cannot review, restrict, or remediate agent access until they know exactly what the agent estate contains.
- Identity Attribution: Identity attribution is the ability to determine which entity performed an action and under what authority. For AI agents, it requires separate identities, structured logs, and traceable decision records so investigations can distinguish human intent from autonomous execution.
- Continuous visibility: The ability to observe control operation, exceptions, and remediation as they happen across systems. In identity and governance programmes, continuous visibility means teams can trace who approved what, what changed, and whether the control actually executed without waiting for a later review cycle.
- Inventory Debt: The gap between what a team believes exists and what is actually running in production. In AI agent environments, inventory debt creates hidden access paths, weak accountability, and delayed remediation because security decisions are based on stale records.
What's in the full article
Onyx's full article covers the operational detail this post intentionally leaves for the source:
- The step-by-step week-one onboarding workflow used to surface hidden AI agents in customer environments
- The specific patterns that caused approved inventories to diverge from the actual agent population
- The 90-day operational model for keeping discovery, ownership, and remediation current
- The practical examples of high-risk agents found during initial scans and how they were triaged
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or programme maturity, it is worth exploring.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org